Phishing Simulation Click Rates Are Not Evidence of Lower Risk
Three large field studies covering 46,000+ employees found little benefit from common phishing training. See what organisations should measure and do instead.
Governance, human risk and regulatory effectiveness in the NIS2 and SOC 2 era.
Three large field studies covering 46,000+ employees found little benefit from common phishing training. See what organisations should measure and do instead.
Companies measure IT risk in detail, but many still struggle to measure human risk. Why the next maturity step in cybersecurity is turning awareness into measurable risk management.
A precise breakdown of NIS2 Article 20 management body training requirements. What the Directive mandates, what it leaves open, and what organisations should be prepared to demonstrate.
A precise breakdown of NIS2 Article 20. What management bodies must approve, oversee, and why cybersecurity is now a board-level liability issue.
A practical breakdown of NIS2 Article 21: what it requires, what to demonstrate during supervisory review, and where national implementation stands in July 2026.